incident-response-trainer
Mock scenarios · Rule-based grading
CatalogOverviewSnapshot
← Back to catalog
CybersecuritymediumInsider Data LeakHigh asset
Scenario

Departing engineer downloaded full customer export 36h before resignation effective date

A medium Cybersecurity scenario on Insider Data Leak.

Practice this scenario

Start a graded attempt against this scenario. Your response is scored by the same deterministic rubric used across the catalog. Email and evidence content stay hidden until you start.

Launches this exact scenario. One of 5 templates in this Track + Difficulty pool.

catalog id · insider-data-leak-departing-eng

Training alignment

What this scenario practices, mapped to recognized frameworks.

Educational mapping only. Not a compliance attestation.

What this trains
  • Insider-risk-aware data triage
  • Evidence-preserving departing-employee response
MITRE ATT&CKmitre-attack
  • Exfiltration Over Web Service · ExfiltrationT1567 · TA0010
    MappedHigh confidence

    Trains defensive triage of insider-style web-service outbound transfers.

MITRE D3FENDmitre-d3fend
  • User Behavior AnalysisD3-UBA
    MappedHigh confidence

    Trains the behavior-analysis posture that surfaces anomalous departing-user activity.

  • User Account PermissionsD3-UAP
    MappedMedium confidence

    Trains the permission-scoping control that limits departing-user blast radius.

NIST CSF 2.0nist-csf-2
  • Data Security · ProtectPR.DS · PR
    MappedHigh confidence

    Trains the data-security baseline against insider exfiltration.

NIST SP 800-61r3nist-sp-800-61r3
  • IR lifecycle phaseDetection & Analysis
    MappedHigh confidence

    Trains evidence-aware triage of insider data movement.

  • IR lifecycle phasePost-Incident Activity
    MappedMedium confidence

    Trains HR/legal coordination and lessons-learned discipline.

CISA Cybersecurity Performance Goalscisa-cpg
  • Revoking Credentials for Departing Employees2.D
    MappedHigh confidence

    Trains the departing-credentials baseline.

  • Secure Sensitive Data2.I
    MappedMedium confidence

    Trains the sensitive-data control under departure pressure.

CIS Controls v8cis-controls
  • Data ProtectionControl 3
    MappedHigh confidence

    Trains the data-protection control the scenario exercises.

  • Account ManagementControl 5
    MappedHigh confidence

    Trains the account-lifecycle control around the departing user.